CMMC Guide · Levels
CMMC Levels Compared: Which Level Does Your Company Need?
CMMC has three levels. Level 1 covers basic protection of Federal Contract Information (FCI) with 15 requirements. Level 2 protects Controlled Unclassified Information (CUI) with the 110 requirements of NIST SP 800-171. Level 3 adds 24 enhanced requirements for the most sensitive programs. Your contract, not your company, sets the level.
The three CMMC levels side by side
| Level 1 | Level 2 | Level 3 | |
|---|---|---|---|
| Protects | FCI | CUI | CUI in the most critical programs |
| Requirements | 15, from FAR 52.204-21 | 110, from NIST SP 800-171 Rev 2 | Level 2 plus 24 from NIST SP 800-172 |
| Assessed by | Your company | Your company or a C3PAO, as the contract states | DCMA DIBCAC (government) |
| How often | Every year | Every three years | Every three years |
| To pass | All 15 met | All 110 met, or at least 88 points with a short plan of action | All met, or at least 80% with a short plan of action |
| Plan of action (POA&M) | Not allowed | Allowed for limited items; close within 180 days | Allowed for limited items; close within 180 days |
| Annual affirmation | Yes | Yes | Yes, for both Level 2 and Level 3 |
| Prerequisite | None | None | Final Level 2 (C3PAO) status |
| Allowed in new contracts today | Yes (Self) | Self only; C3PAO paused | Paused |
Which CMMC level do you need?
Answer three questions, in this order:
What does the contract say?
Solicitations that include CMMC name the required level and assessment type through DFARS 252.204-7021. If you are a subcontractor, your prime will pass this requirement to you.
Will you handle CUI?
If you will process, store or transmit CUI, you need at least Level 2. If you will handle only FCI, Level 1 is enough.
Is it a critical program?
Level 3 applies only when the Department of War specifies it for its most critical programs and technologies. Most contractors will never need it.
Not sure which information you hold? See FCI vs CUI.
Can a company hold more than one CMMC level?
Yes. CMMC status is recorded per information system, so a company can keep CUI in a separate, smaller environment at Level 2 while the rest of its network stays at Level 1. A Level 2 status also satisfies Level 1 for the same scope. Level 3 always sits on top of a Final Level 2 (C3PAO) status for the same systems.
How to draw those boundaries: CMMC scoping.
Questions about CMMC levels
Are there still five CMMC levels?
No. The first version of CMMC had five levels. The current program, often called CMMC 2.0, has three: Level 1, Level 2 and Level 3.
Does Level 2 always require a third-party assessment?
No. The contract states whether Level 2 is a self-assessment or a C3PAO certification assessment. While Phase 2 is suspended, new contracts may require only the self-assessment.
Can we choose a higher level than the contract requires?
Yes. Contracting officers accept the required level or higher, so a higher status never disqualifies you. It does, however, take more effort to achieve and maintain.
Know your level. Plan the work.
CMMCMARK helps defense contractors confirm their CMMC level, prepare for assessment and train the people involved.
Prefer the phone? Call +1 (202) 867-8444.
Sources
- 32 CFR Part 170, CMMC Program (§ 170.14–170.18, 170.21, 170.22)
- FAR 52.204-21 · NIST SP 800-171 Rev 2 · NIST SP 800-172
- DoW CIO, Implementing Suspension of CMMC Phase II (July 13, 2026)
